Impact
Premiere Pro has a heap-based buffer overflow vulnerability that can lead to arbitrary code execution when a user opens a crafted file. This overflow, identified as CWE-122, occurs during processing of certain data within the application, potentially allowing an attacker to run code with the privileges of the current user.
Affected Systems
Adobe Premiere Pro (all versions) – the CVE notes that any installed instance of Premiere Pro is affected; specific versions are not listed in the advisory.
Risk and Exploitability
The CVSS score of 7.8 rates the vulnerability as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction; an attacker would need to supply a malicious file that the victim opens, which may limit the attack surface but still allows potential compromise when unsuspecting users engage.
OpenCVE Enrichment